Security

Google Workspace offboarding, done without data loss

Offboarding a Google Workspace user means transferring Drive ownership, delegating or archiving the mailbox, reassigning calendar events, revoking app passwords and third-party tokens, and only then suspending the account. That sequence runs to 11 steps in the order we work through, and deleting the account first destroys data that ownership transfer would have preserved.

Offboarding facts
Correct first stepTransfer Drive ownership, not suspend
Suspended accountData retained, licence still consumed
Archived user licenceCheaper than a full seat, keeps Vault searchable
Calendar eventsRecurring events need a new organiser explicitly
App passwords and tokensRevoked separately from the password reset
Typical time per leaver20–35 minutes done properly

The sequence, in order

Reset the password and sign the user out of all sessions first, so nothing changes underneath you. Then revoke OAuth tokens and application-specific passwords, which survive a password reset and are routinely missed. Then transfer Drive ownership to the named successor. Then handle mail: either delegate the mailbox to a manager for a defined period, or move the account to an archived licence so Vault keeps it searchable.

Calendar comes next, and it is the step people skip. Recurring events organised by the leaver do not transfer with the account, so a weekly team meeting quietly loses its organiser and stops being editable. Finally, suspend the account. Deletion, if it happens at all, happens after the retention period you have agreed in writing.

  • Reset password and terminate all active sessions
  • Revoke OAuth grants and app-specific passwords explicitly
  • Transfer Drive ownership to a named successor
  • Delegate the mailbox or move to an archived licence
  • Reassign recurring calendar events and room bookings
  • Suspend, do not delete; document the retention decision

The licence question nobody asks early enough

A suspended account still consumes a licence. Organisations with steady turnover accumulate suspended accounts and pay full seat price for each one indefinitely, which is one of the more common sources of quiet Workspace overspend we find.

The archived user licence exists precisely for this: it costs materially less than a full seat, keeps the data searchable in Vault, and removes interactive access. For any organisation with a retention obligation and turnover above a handful of people a year, the arithmetic is not close.

What goes wrong in practice

Three failures recur. Shared drive membership is removed before anyone checks whether the leaver was the only manager, which leaves a drive nobody can administer. Files in My Drive that were shared with the team are lost from view when the account is suspended, because sharing survives but discovery does not. And third-party integrations authenticated as the leaver stop working days later, usually the integration that syncs something to finance.

All three are prevented by a written checklist that includes a discovery step rather than starting with revocation. Twenty minutes of checking beats a week of reconstruction.

Making it repeatable

Offboarding is a process problem, not a technical one. The technical steps are unremarkable; the reason they go wrong is that the person doing them is under time pressure and working from memory on a Friday afternoon.

We hand over a one-page checklist tied to your actual org structure, with the successor for each department already named, plus an optional Apps Script that performs the mechanical steps and writes an audit line per leaver. The audit line is what lets you answer, months later, exactly what happened to someone's data.

What we see that others don't say

Suspension and deletion behave completely differently for data: a suspended account retains everything and can be recovered, while deletion starts an irreversible clock, which is why the correct offboarding sequence always ends in suspension and never begins with deletion.

What this doesn't cover

  • This does not cover HR or employment process. We handle the tenant; access timing relative to a termination conversation is your decision.
  • We do not advise on how long to retain a leaver's data. That is a legal and regulatory judgement; we implement the period you specify.
  • Third-party SaaS accounts outside Workspace are not covered here beyond revoking their Workspace tokens.
  • Deletion is irreversible past its recovery window. We will not delete accounts on a verbal instruction.

Questions we get asked

Should we suspend or delete a Google Workspace account when someone leaves?
Suspend. Suspension retains all data and is reversible; deletion starts an irreversible clock. If licence cost is the concern, move the account to an archived user licence rather than deleting it.
What happens to a leaver's Drive files?
Files in shared drives stay put. Files in My Drive remain owned by the suspended account and become hard to discover, so ownership must be transferred to a named successor before suspension.
Do recurring calendar events survive offboarding?
Not usefully. Events organised by the leaver lose their organiser and cannot be edited, so recurring meetings and room bookings need a new organiser assigned as an explicit step.
Does resetting the password cut off all access?
No. Application-specific passwords and existing OAuth tokens survive a password reset and must be revoked separately, which is the step most commonly missed.

How this page is verified

Reviewed by Pearl Lemon Cloud security desk, Workspace security and compliance reviewers. Last checked .

  • Suspension, deletion and archived user licence behaviour reflect Google Workspace Admin Help documentation as of 2026-08-06.
  • Token and app-password persistence after password reset per Google Account security documentation, 2026-08-06.
  • Timing observations are Pearl Lemon Cloud service-desk data to 2026-08-06.

Sources you can check

Related pages

Get your offboarding runbook

We audit existing suspended accounts, cut the licences you no longer need, and hand over a checklist tied to your own department owners.